Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A0A3B8D6229821FE11328EDCD3352B32B0D6A89AD60657E6CADDC75917CEC44F93B843 |
|
CONTENT
ssdeep
|
3072:Pw2K0+mrMj31K6lF8UtDOJ/GbF79q909r9w9W9P9J9N9+eJ:Pw2K0+jj3E6lF8UtDONGZ4eJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c10f3e2ecccd3e2 |
|
VISUAL
aHash
|
ff0000001900ffff |
|
VISUAL
dHash
|
3afcf0b231c9c404 |
|
VISUAL
wHash
|
ff000000ff00ffff |
|
VISUAL
colorHash
|
03000e00000 |
|
VISUAL
cropResistant
|
2050263638581800,737b6b4c4495c564,b080c09692b080a2,a2aa9429ab94a2a2,92a2922d2d828282,a2a2a83222a0a2a2,a2a2a44b7b84a2a2,a2a284e9bb80a2a2,a2a8a6299ba4a2a2,828a864949848282,a0a894a92d84a0a0,00000c0c63032323,bafcf0b2b4b16be0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 935 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)